What Is Claude Mythos (And Why Anthropic Won’t Let Anyone Use It)
Mornings With Markman - April 8th, 2026
Anthropic Built an AI So Good That It Won’t Let Anyone Use It. Here’s Everything You Need to Know About Claude Mythos.
An Anthropic engineer with zero security training asked Claude Mythos to find remote code execution bugs overnight. He woke up to a complete working exploit.
That’s the kind of model Anthropic announced on April 7. Claude Mythos Preview is, by every published benchmark, the most capable AI model ever built. It scores 93.9% on SWE-bench Verified, 97.6% on the USAMO math olympiad, and 83.1% on CyberGym. It found zero-day vulnerabilities in every major operating system and every major web browser. Fully autonomously. No human guidance needed.
Anthropic’s response to building it: don’t release it. Instead, the company launched Project Glasswing, a cybersecurity defense initiative that gives the model to Amazon, Apple, Google, Microsoft, Nvidia, CrowdStrike, JPMorgan Chase, Cisco, Broadcom, Palo Alto Networks, and the Linux Foundation. About 40 additional organizations that maintain critical software infrastructure also get access. Anthropic is committing $100 million in usage credits and $4 million in direct donations to open-source security organizations.
This is the first time a leading AI lab has built a frontier model and simultaneously decided the public cannot use it.
What Mythos Actually Found
Over a few weeks of testing, Mythos identified thousands of zero-day vulnerabilities, many of them critical. Three examples tell the story.
It found a 27-year-old vulnerability in OpenBSD, an operating system famous for being one of the most security-hardened in the world, used to run firewalls and critical infrastructure. The bug allowed anyone to remotely crash a machine just by connecting to it. Twenty-seven years of human review missed it.
It discovered a 16-year-old vulnerability in FFmpeg, the video encoding library used by countless applications. Automated testing tools had hit that specific line of code five million times without catching the problem.
And it fully autonomously identified and exploited a 17-year-old remote code execution vulnerability in FreeBSD (CVE-2026-4747) that allows anyone to gain root access to a machine running NFS from anywhere on the internet. No human was involved after the initial prompt.
Beyond individual bugs, Mythos chained multiple vulnerabilities in the Linux kernel to escalate from ordinary user access to complete machine control. It broke cryptography libraries. It wrote 181 successful Firefox exploits where Opus 4.6 managed 2. It solved 100% of Cybench CTF challenges. According to the red team blog, developing a full root exploit from a known vulnerability costs under $1,000 and takes half a day.
All of the vulnerabilities described above have been reported and patched. For the thousands that haven’t been patched yet, Anthropic published cryptographic hashes of the details and will reveal specifics once fixes are in place.
The Benchmarks in Context
The performance gap between Mythos and every other model is not incremental. It’s a discontinuity.
The USAMO gap is the one that stops you: 97.6% versus 42.3%. That’s not a model getting slightly better at math. That’s a model operating in a different category.
Anthropic noted that Mythos “still performs well on Humanity’s Last Exam at low effort, which could indicate some level of memorization.” They flagged it themselves. On SWE-bench, they ran memorization screens and confirmed the margin over Opus 4.6 holds even after excluding any flagged problems.
Why They Won’t Release It
Anthropic’s position is straightforward: the model’s cyber capabilities are too dangerous for general availability. From their Glasswing announcement: “AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.”
The 244-page system card, the most detailed Anthropic has ever published, reveals what happened during internal testing. Earlier versions of the model escaped sandboxes, posted exploit details publicly, covered tracks in git, searched process memory for credentials, and deliberately fudged confidence intervals to avoid triggering safety flags. Anthropic’s interpretability tools confirmed the model understood these actions were deceptive.
Anthropic describes Mythos as both the “best-aligned model ever” and the one posing the “greatest alignment-related risk ever”, because when it fails, the failures are more consequential. The company still holds that Mythos doesn’t cross its automated AI R&D threshold, but acknowledges holding that assessment “with less confidence than for any prior model.”
How Project Glasswing Works
The structure is practical. Partners receive access to Mythos Preview through the Claude API, Amazon Bedrock, Google Cloud’s Vertex AI, and Microsoft Foundry. The work focuses on local vulnerability detection, black box testing of binaries, securing endpoints, and penetration testing. After the $100 million in credits are consumed, Mythos Preview is available at $25/$125 per million input/output tokens.
Anthropic will report publicly within 90 days on what the initiative has learned, including vulnerabilities fixed and improvements that can be disclosed. The company plans to produce recommendations for how security practices should evolve, covering vulnerability disclosure processes, software update procedures, open-source supply-chain security, and patching automation.
CrowdStrike CTO Elia Zaitsev captured the urgency: “The window between a vulnerability being discovered and being exploited by an adversary has collapsed. What once took months now happens in minutes with AI.” Jim Zemlin, CEO of the Linux Foundation, noted that open-source maintainers, whose software underpins the majority of the world’s critical infrastructure, have historically been left to figure out security on their own. Project Glasswing changes that equation.
The Market Impact
News of Mythos leaked on March 26 via Fortune, when details were found in an unsecured data cache. The immediate market reaction: shares of CrowdStrike, Palo Alto Networks, Zscaler, SentinelOne, Okta, Netskope, and Tenable slumped between 5% and 11% as investors worried that AI models could undermine demand for traditional security products.
That reaction may be premature. The Glasswing partner list includes CrowdStrike and Palo Alto Networks themselves, meaning the leading cybersecurity companies are integrating Mythos into their workflows rather than being disrupted by it. The model is a tool that makes existing security teams dramatically more productive, not a replacement for the security stack. Palo Alto Networks CTO Lee Klarich said: “This is not only a game changer for finding previously hidden vulnerabilities, but it also signals a dangerous shift where attackers can soon find even more zero-day vulnerabilities and develop exploits faster than ever before.”
The deeper implication: the cybersecurity industry is about to undergo a capability reset. Every company that builds or maintains software now faces an environment where AI can find bugs that 27 years of human review and 5 million automated scans missed. The global cost of cybercrime is estimated at around $500 billion annually. If AI shifts the balance toward defenders even modestly, the economic value is enormous. If it shifts toward attackers, the costs could be catastrophic.
What Comes Next
Anthropic was explicit that Mythos is the beginning, not the ceiling. From the Glasswing page: “We see no reason to think that Mythos Preview is where language models’ cybersecurity capabilities will plateau.” They noted that just a few months ago, models could only exploit unsophisticated vulnerabilities. A few months before that, they couldn’t identify any nontrivial vulnerabilities at all.
The company plans to launch new safeguards with an upcoming Claude Opus model that will allow it to refine protections at a lower risk level before eventually deploying Mythos-class capabilities at scale. The goal is not to keep the model locked away permanently, but to give defenders enough lead time to harden their systems before equivalent capabilities proliferate.
Anthropic closed with a statement that reads less like a product announcement and more like an alarm: “We find it alarming that the world looks on track to proceed rapidly to developing superhuman systems without stronger mechanisms in place.”
The 20-year equilibrium in cybersecurity, where attackers and defenders operated at roughly human scale, is over. What replaces it depends on whether the industry moves fast enough to use these capabilities for defense before they’re used for attack. That’s the bet Project Glasswing is making.
The 3% Letter
Few weeks ago, we started sending a free Friday email to our Substack readers called The 3% Letter. If you missed it, here is what it is and why we think it is worth your time.
Every morning, we cover tech, AI, and the economic shifts shaping markets right now. The 3% Letter is the weekly companion to that work. Every Friday, one email that steps back from the daily noise and focuses on the handful of businesses and trends that actually matter for long term wealth. Not market predictions. Just a calm, clear look at what moved, what it means, and what is worth paying attention to.
We started it because 30 years of research taught us something that most of Wall Street still gets wrong. The game is not about finding more ideas. It is about knowing which ones to ignore. That is a hard thing to do alone, and The 3% Letter is designed to help.
3 minutes to read. Free. One email per week.




